New Search

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1 as used in Python PyXML w3c-libwww and other software allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read a different vulnerability than CVE-2009-2625.

oval:org.mitre.oval:def:10671

The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets which facilitates phishing attacks.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • Red Hat Enterprise Linux 4
  • Oracle Linux 4
  • CentOS Linux 4
Class:
vulnerability
Reference(s):
  • CVE-2005-0237
Product(s):